Executive brief
WP Event Solution is a WordPress plugin for managing event bookings and ticketing on websites. This vulnerability allows unauthenticated attackers to access pages and perform actions they should not be permitted to do, such as viewing other users' event data or modifying event information without proper authorization.
Technical details
The vulnerability is a broken access control issue in WP Event Solution plugin versions up to and including 4.1.22, allowing unauthenticated attackers to bypass authorization checks. The plugin fails to properly validate user permissions before allowing access to sensitive functionality or data. Attackers do not need to authenticate and can access restricted content or actions over the network. The vulnerability affects unauthorized data access and potential modification of event records. A patch is available in version 4.1.23 and later.
Affected products
- Arraytics WP Event Solution <=4.1.22
Timeline
- 2026-09-02: disclosed
- 2026-09-01: patched: version 4.1.23 released